ModSecurity Handbook is the definitive guide to ModSecurity, a popular open source web application firewall. Written by Ivan Ristic, who designed and wrote much of ModSecurity, this book will teach you everything you need to know to monitor the activity on your web sites and protect them from attack. Situated between your web sites and the world, web application firewalls provide an additional security layer, monitoring everything that comes in and everything that goes out. They enable you to perform many advanced activities, such as real-time application security monitoring, access control, virtual patching, HTTP traffic logging, continuous passive security assessment, and web application hardening. They can be very effective in preventing application security attacks, such as cross-site scripting, SQL injection, remote file inclusion, and others. Considering that most web sites today suffer from one problem or another, ModSecurity Handbook will help anyone who has a web site to run. The topics covered include:
Installation and configuration of ModSecurity
Logging of complete HTTP traffic
Rule writing
IP address, session, and user tracking
Session management hardening
Whitelisting, blacklisting, and IP reputation management
Advanced blocking strategies
Integration with other Apache modules
Working with rule sets
Virtual patching
Performance considerations
Content injection
XML inspection
Writing rules in Lua
Extending ModSecurity in C
The book is suitable for all reader levels: it contains step-by-step installation and configuration instructions for those just starting out, as well as detailed explanations of the internals and discussion of advanced techniques for seasoned users. A comprehensive reference manual is included in the second part of the book. Other digital formats (PDF or EPUB) can be obtained directly from the author, at feistyduck.com.
Well written, lots of very useful information. Let down by the index and the eccentricity of the underlying platform. Definitely recommend having the electronic version, even if it is just for searching.